SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14165

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Tuleap Enterprise Edition versions 17.0 to 17.5 are vulnerable to an authorization bypass due to a flaw that allows attackers to exploit user-controlled keys, potentially granting them unauthorized access to other users' data. Organizations using these versions should prioritize patching this vulnerability to mitigate the risk of data breaches and unauthorized information disclosure. Immediate action is essential for any entity relying on Tuleap for project management and collaboration.

CVE
CVE-2026-14165
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users without authorization.